CSV
14,766 results for "vulnerability" Page 146
CVE-2020-0796 CRITICAL KEV Exploit

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

Mar 12, 2020 8 affected product(s) NVD
10.0
CVSS
99.8%
EPSS
⚡ 99.9
CVE-2020-5722 CRITICAL KEV Exploit

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.

Mar 23, 2020 1 affected product(s) NVD
9.8
CVSS
84.4%
EPSS
⚡ 94.5
CVE-2020-8599 CRITICAL KEV Exploit

Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.

Mar 18, 2020 3 affected product(s) NVD
9.8
CVSS
11.9%
EPSS
⚡ 72.8
CVE-2019-16072 CRITICAL

An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

Mar 20, 2020 1 affected product(s) NVD
9.8
CVSS
25.9%
EPSS
⚡ 47
CVE-2020-8598 CRITICAL

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.

Mar 18, 2020 7 affected product(s) NVD
9.8
CVSS
13.2%
EPSS
⚡ 43.2
CVE-2020-8868 CRITICAL

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the __service__ user account. The product contains a hard-coded password for this account. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-9553.

Mar 23, 2020 1 affected product(s) NVD
9.8
CVSS
9.5%
EPSS
⚡ 42
CVE-2020-9347 CRITICAL

Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do not plan to add CSV constraints to their own products

Mar 16, 2020 15 affected product(s) NVD
9.8
CVSS
7.8%
EPSS
⚡ 41.5
CVE-2020-0872 CRITICAL

A remote code execution vulnerability exists in Application Inspector version v1.0.23 or earlier when the tool reflects example code snippets from third-party source files into its HTML output, aka 'Remote Code Execution Vulnerability in Application Inspector'.

Mar 12, 2020 1 affected product(s) NVD
9.6
CVSS
10.1%
EPSS
⚡ 41.4
CVE-2020-1747 CRITICAL

A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.

Mar 24, 2020 7 affected product(s) NVD
9.8
CVSS
5.4%
EPSS
⚡ 40.8
CVE-2020-3792 CRITICAL

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

Mar 25, 2020 6 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2020-3793 CRITICAL

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

Mar 25, 2020 6 affected product(s) NVD
9.8
CVSS
4.9%
EPSS
⚡ 40.7
CVE-2020-8600 CRITICAL

Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.

Mar 18, 2020 4 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2020-8137 CRITICAL

Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.

Mar 20, 2020 1 affected product(s) NVD
9.8
CVSS
4.3%
EPSS
⚡ 40.5
CVE-2020-3795 CRITICAL

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

Mar 25, 2020 6 affected product(s) NVD
9.8
CVSS
4.2%
EPSS
⚡ 40.5
CVE-2020-3797 CRITICAL

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

Mar 25, 2020 6 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2019-13192 CRITICAL

Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to execute arbitrary code on the device.

Mar 13, 2020 305 affected product(s) NVD
9.8
CVSS
3.8%
EPSS
⚡ 40.3
CVE-2020-6072 CRITICAL

An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this vulnerability.

Mar 24, 2020 2 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2020-0902 CRITICAL

An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'.

Mar 12, 2020 1 affected product(s) NVD
9.8
CVSS
2.9%
EPSS
⚡ 40.1
CVE-2019-13172 CRITICAL

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device.

Mar 13, 2020 1 affected product(s) NVD
9.8
CVSS
3.0%
EPSS
⚡ 40.1
CVE-2019-17559 CRITICAL

There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

Mar 23, 2020 4 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.1